Malware again

This one was tricky because there was a globalroot path and a file name listed as userinit.exe under %systemroot%\system32 which in fact was us?rinit.exe!!! With the Command Prompt, I saw that strange name but not within the Windows Explorer resp. the Windows Explorer showed me that us?rinit.exe as a userinit.exe. Because you cannot use the question mark within file names in Windows it was highly possibly altered via Linux (question marks are allowed there) or some hex editor maybe.

Bad files found onto that system:

userinit.exe (us?rinit.exe), rundll32.exe (malware one), ntload.exe, clerma.dll

Here are some Screenshots:






This entry was posted in Uncategorized and tagged , . Bookmark the permalink.

Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out /  Change )

Google+ photo

You are commenting using your Google+ account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )


Connecting to %s